That's not true. GrapheneOS is heavily focused on privacy and offers much better privacy than CalyxOS. See https://grapheneos.org/features for the privacy and security features offered beyond AOSP. Unlike CalyxOS, we aren't listing AOSP features as our own.
CalyxOS has a leaky firewall which apps can bypass and a leaky VPN tethering implementation. GrapheneOS has a Network toggle without those leaks and prefers the approach of fine-grained VPNs rather than using the same tunnel for everything. We want real per-profile VPNs rather than making more devices use the same VPN, especially in a leaky way.
> For example: Calyx provides MicroG. This means you can talk to Google Play services, though in a better, more privacy-conscious way. MicroG is an open implentation of Google Play Services.
GrapheneOS has https://grapheneos.org/usage#sandboxed-play-services which is able to provide much better app compatibility, far more functionality and without the privacy/security sacrifices of microG. microG lacks the same security checks and key pinning of Play. It doesn't avoid trusting Play because the apps using Play are using the Play client libraries. microG is an additional trusted party.
> This could technically be abused, though Calyx takes lots of precautions to prevent that.
They simply limit it to microG and the Play services signature, which was our suggestion. That isn't taking a lot of precautions. It is abused because apps are tricked into giving their data to an app without the same security model/checks and key pinning (microG) is
> GrapheneOS with their security-first approach don't deem this worth the risk.
No, we took a better approach instead.
https://grapheneos.org/usage#sandboxed-play-services
> So with apps requiring play services you don't get push messages and network-based location checks, among others.
Push works fine with many apps without Play. GrapheneOS has support for using Play in a sandbox.
> So, do you want an allround phone to use everyday (and use things like Uber, Facebook, etc) but more private and secure than AOSP, take Calyx.
Those apps work fine on GrapheneOS. CalyxOS isn't more private and more secure than AOSP. CalyxOS includes a lot more proprietary services (Google, WhatsApp, etc.) than AOSP. For the most part, they're making changes which quite easily hurt privacy and security.
> Do you want security over everything and are willing to compromise a bit on functionality and app compatibility (some apps will refuse to run without google play), pick Graphene.
This is a highly inaccurate portrayal of what GrapheneOS provides and the decision making process. GrapheneOS values privacy and usability very highly. It balances those with security.
What really defines GrapheneOS is that we aim to implement things in a proper way that cannot be bypassed by adversaries. A privacy feature that's simply worked around is not much of a privacy feature.